CVE-2026-19926 | Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1 open-ils.fielder OpenSRF Service /osrf-gateway-v1 sql injection
A vulnerability labeled as critical has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-19926. The attack can be executed remotely. Additionally, an exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More